← volver
CVE-2021-27625

CVE-2021-27625

CVSS 5.9 MEDIUMEPSS 1.2%CWE-787
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.9EPSS 1.2%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
09 jun 2021Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method IgsData::freeMemory() which will trigger an internal memory corruption error in the system causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →